Press Release: Agencies Issue Joint Statement on Handling of Highly Sensitive Information During Bank Examinations
AI Analysis
On 2026-07-16, the FDIC, Federal Reserve Board, and OCC issued a joint statement on how exam teams should handle highly sensitive information during bank examinations. The key compliance issue is not a new substantive prudential rule, but a procedural shift toward tighter controls, including on-site review and other methods intended to reduce cybersecurity and confidentiality risk.
Key dates
- 2026-07-16
- FDIC, Federal Reserve Board, and OCC issued the joint statement on handling highly sensitive information during examinations
- 2026-07-16 Deadline
- Affected banks must be notified of any potential or confirmed material data breach involving confidential supervisory information no later than 72 hours after discovery, unless legal restrictions apply
Suggested considerations
- Compliance teams may wish to review examination response procedures for materials that could be treated as highly sensitive, including technology diagrams, penetration test results, detailed control-weakness reports, and similar data.
- Banks may wish to establish an internal process for flagging sensitive examination materials to examiners and documenting the basis for the sensitivity designation.
- Firms may wish to confirm that exam-response playbooks address on-site review, direct-from-system access, redaction, and summarization options for especially sensitive documents.
- Compliance and information security teams may wish to ensure escalation paths are ready if examiners disagree about whether information should receive enhanced handling.
- Firms may wish to verify incident-response and supervisory-notification procedures can support rapid engagement if a material supervisory-information breach is suspected.
What changed
The agencies said they will use a coordinated approach to identify highly sensitive data and documents during examinations and will apply enhanced handling procedures to reduce cybersecurity risk while preserving examiner access. The statement says review may occur on-site rather than by transferring materials onto agency systems, and the agencies may use other protective methods such as direct digital review from the bank's own systems or review of redacted or summarized materials where appropriate. The agencies also stated they will notify affected banks of any potential or confirmed material data breach involving confidential supervisory information as soon as practicable and no later than 72 hours after discovery, unless legal restrictions apply. The FDIC's summary states the joint sta
Compliance impact
The publication signals heightened expectations for how examination materials are accessed, reviewed, and protected, especially where cybersecurity exposure is a concern. The agencies frame the change as a confidentiality and operational-control measure rather than a new regulatory standard, but a material breach can trigger prompt bank notification obligations and supervisory scrutiny.
Who is affected
Related regulations
References
AI-generated analysis. May contain errors or omissions — verify with the original FDIC source before acting. Full disclaimer.
What the FDIC said
PRESS RELEASE | JULY 16, 2026 Agencies Issue Joint Statement on Handling of Highly Sensitive Information During Bank Examinations WASHINGTON — The federal bank regulatory agencies today issued a joint statement describing enhanced security procedures for review of highly sensitive information in connection with…
Extract from FDIC . Read the full notice at the source for the authoritative text.